Description
OpenClaw before 2026.3.28 accepts unbounded concurrent unauthenticated WebSocket upgrades without pre-authentication budget allocation. Unauthenticated network attackers can exhaust socket and worker capacity to disrupt WebSocket availability for legitimate clients.
Problem types
CWE-770: Allocation of Resources Without Limits or Throttling
Product status
Any version before 2026.3.28
2026.3.28 (semver)
Credits
wang dong (@topsec-bunney)
References
github.com/...enclaw/security/advisories/GHSA-f44p-c7w9-7xr7 (GitHub Security Advisory (GHSA-f44p-c7w9-7xr7))
www.vulncheck.com/...a-unbounded-pre-auth-websocket-upgrades (VulnCheck Advisory: OpenClaw < 2026.3.28 - Denial of Service via Unbounded Pre-auth WebSocket Upgrades)